HKMA C-RAF status + Hong Kong banking sector adoption. ADOPTION: ALL ~150+ HKMA AUTHORISED INSTITUTIONS (AIs) mandated to participate in CFI + C-RAF + complete annual self-assessment + 3-year independent review + ongoing supervisory dialogue; major participants include local banks (HSBC + Hang Seng Bank + Standard Chartered Hong Kong + Bank of China Hong Kong + DBS Hong Kong + Citi + UBS + Goldman Sachs + Morgan Stanley + many more); RLBs + DTCs + foreign banks operating in Hong Kong; ~100 percent participation as mandated. CYBER MATURITY PROGRESS: significant industry maturity improvement since 2016 launch; most AIs at Intermediate (Level 3) or higher maturity; HIGH-inherent-risk AIs typically Intermediate-to-Advanced (Level 3-4); v2.0 raised maturity expectations + added iCAST requirement. iCAST EXECUTION: significant industry experience executing iCAST + remediation; sectoral lessons learned + threat-intel sharing via CISP. SUPERVISORY ENGAGEMENT: ongoing HKMA supervisory dialogue + cyber-incident reporting + sectoral coordination + sectoral exercises (table-top + cyber wargames). CYBER INTELLIGENCE SHARING PLATFORM (CISP) ADOPTION: active participation by ~150 AIs + threat-intel sharing + IOC distribution + sectoral SOC coordination + integration with HKCERT + commercial feeds. PROFESSIONAL DEVELOPMENT PROGRAMME (PDP): thousands of Hong Kong cyber professionals certified via CCSO + Cyber Risk Management programs + ongoing CPD + sectoral talent pipeline. KEY 2024-2025+ DIRECTIONS: (a) AI + GENERATIVE AI CYBER RISK + governance; (b) QUANTUM-RESISTANT CRYPTOGRAPHY readiness + transition planning; (c) CLOUD + MULTI-CLOUD + HYBRID security maturity; (d) RANSOMWARE + EXTORTION + payment policy + insurance + sanctions; (e) SUPPLY CHAIN + 3rd-PARTY + SBOM; (f) EU DORA COORDINATION for AIs with EU operations; (g) GEOPOLITICAL CYBER + nation-state threats; (h) VIRTUAL BANKING + FinTech + DeFi cybersecurity; (i) POST-COVID HYBRID + remote work + zero trust; (j) ASEAN + APAC SECTORAL CYBER COORDINATION + cross-jurisdiction. RECENT HONG KONG CYBER INCIDENTS: ongoing sectoral cyber incidents + ransomware + supply chain + phishing + executive engagement + HKMA-led sectoral exercises + lessons learned. INFLUENCE: HKMA C-RAF widely cited as leading APAC banking cybersecurity supervisory framework + influential on Singapore MAS + AMBD Brunei + BSP Philippines + Bank Negara Malaysia + Bank Indonesia + State Bank of Vietnam + sectoral coordination.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.